PCI advice for charities taking credit card payments [updated 2026 – PCI V4.0.1]

Credit cards and related cashless payments are a faster, simpler payment option for charities to facilitate donations. And as more and more people use their mobile phones for payments and donations, whether online or as contactless options, they are representing a far higher proportion of payments for many charities.

Accepting credit card payments, however, does require additional security measures to be put in place to ensure your organisation is Payment Card Industry Data Security Standard (PCI DSS) compliant. In this article, we give an overview of some of the key areas charities should consider to stay secure and compliant.

The rise in cashless donations to charities

Cashless payments linked to payment cards have risen significantly as a proportion of all transactions in recent years, rising especially quickly during the pandemic. In this report, the banking body UK Finance claimed that by 2032, less than 6% of all transactions will be in cash.

The trend is also being seen by charities. Research from the Charities Aid Foundation (CAF) shows that digital payments to charities (credit cards, contactless and payments through mobiles) rose significantly at the start of lockdown in March 2020 and remain at a higher level, while cash donations dropped off and remain lower than usual.

As fewer people use cash, the ability to take cashless payments and donations is crucial to charities, but taking any payments by card (credit or debit) does bring a requirement to be PCI DSS compliant.

PCI DSS compliance for charities

It is mandatory for charities which process credit cards to comply with the Payment Card Industry Data Security Standard (PCI DSS).

This is the case even where you use a compliant payment provider like Stripe or Opayo, but doing this does make it much easier to meet your PCI compliance requirements.

PCI DSS compliance is important for three key reasons:

  • It ensures you have in place best-practice security measures that minimise the likelihood of suffering a data breach
  • It means you won’t be liable for fines and additional transaction charges from your bank. They may also withdraw the facility to take payment by credit and debit card if you continue to be non-compliant.
  • If you do suffer a breach and are not PCI compliant, any data breach will risk not only fines but a significant negative impact on all the hard-won support the charity has achieved

If you need to understand more about the principles of PCI DSS compliance, read our Ultimate Guide to PCI Compliance in the UK.

If you want to see how your organisation stands now that PCI DSS v3.2.1 has been retired and PCI DSS v4.0.1 is the only active version of the standard, you can try our free online PCI DSS v4.0.1 Readiness Assessment by clicking here.

PCI Version V4.0.1

The current standard for PCI DSS compliance is PCI DSS v4.0.1. Click here to read about PCI DSS v4.0.1 and what the changes mean for you.

If you need help with your charity’s PCI compliance, call us on 01392 247 110, email info@securious.co.uk or send us a message using the form below.

Advice for the different ways charities take credit card payments

Charities use various options to take credit card payments including:

  • Submitting forms with credit card details on (physical/paper based)
  • By telephone (mail order, telephone order/card holder not present)
  • Through retail outlets (face to face)
  • Via website (Ecommerce)
  • Donation via text message
  • Donation via QR code (scan to donate)

Payment by submitting forms

Charities will sometimes ask for donations to be submitted on paper forms and then sent, or handed to them. Cardholder data would include the full sixteen-digit card number (PAN), the expiry date, and the last three digits of the security number from the back of the card (CVV).

These should not be asked to be transmitted electronically in an unencrypted form, eg simply emailed. If they are posted, or delivered, there needs to be controls in place to keep the details secure. In summary these would include:

  • Controlling who receives the details and ensuring this is an authorised person
  • Immediately processed credit card details or very soon after collection
  • Once processed the credit card data, as a minimum, needs to be masked and ideally destroyed. The first six and last four digits are the maximum allowed to be kept visible, the CVV also needs to be masked.
  • Ideally, unless there is a very good reason to maintain credit card data, the best solution is to process it and shred it immediately.

Payment by telephone (voice)

Part of the charity’s credit card payment process may be to take details over the phone. There is also good practice that should be implemented around this process.

As CVV should never be stored post transaction and with only encrypted or masked PAN allowed . Writing this down to process later is not advised and me more difficult to secure. Processing the payment immediately whilst they are given over the telephone ensures that this does not happen. Beware of telephone recording which will also capture these details. There should be a process in place to ensure that card details are not captured in this way. Stopping the recording whilst the card details are given can prevent this happening.

Payment in person at retail outlets

Charity retail outlets will be using a point-of-sale device normally so that the card details are captured when the card is inserted, and a PIN is required. The most important advice here is to keep these secure. Access by unauthorised personnel, or tampering with the device could be the source of a card data breach. Make sure that staff are trained on how to spot anything unusual with the device and that it is secured.

Payment via Website

Charities using Ecommerce sites providing the opportunity to donate via credit card on a website is also a popular way to receive donations.

There are numerous controls that need to be in place to ensure this is secure. Relying on the compliance of your payment provider (for example, assuming that because they PCI DSS compliant, you automatically will be) has been the route of many credit card breaches recently.

Consider how your website connects to the payment provider and ensure you have your website regularly checked for weaknesses through regular Penetration testing and vulnerability scanning.
Merchants that process, store or transmit credit cards have to comply with the mandatory controls of the Payment Card Industry Data Security Standard (PCI DSS). These are very prescriptive and sometimes understanding the intent of the questions can be confusing.

Engaging with a PCI QSA (Qualified Security Assessor) will make sure that you receive expert advice, and help prevent your charity being the victim of a credit card breach. An additional benefit of following the PCI DSS compliance standard is that it helps charities put the necessary technical and organisational controls in place to help meet their GDPR compliance.

The last thing charities want to do is pay huge fines out of the valuable contributions that have been received, and to lose any of the goodwill of their supporters.

Payment via text message

Some charities and especially large charity events (such as BBC Children In Need) are providing the option for people to donate by sending a text message.

This is a different approach in that the donation is usually added to the user’s mobile phone bill and then passed onto the charity by the mobile phone company (with or without a handling charge). This means there is no direct card payment and PCI compliance is not applicable to the charity in this specific case.

Normally these schemes are set up and managed by a third-party organisation on behalf of the charity and it is essential the charity researches the validity of the scheme to ensure there are no issues and potential reputational consequences if anything goes wrong.

Payment via QR code (‘scan to donate’)

Like many organisations, charities are using QR codes to help potential supporters and donors get onto the right website or app as quickly as possible when they are using their mobile phone.

However, it is also possible to receive one-off donations directly through QR code. This normally involves a payment through the user’s payment card or their PayPal (or similar) account.

As with all other payments via payment card or through PayPal, the charity needs to be PCI DSS compliant to receive donations this way.

Need some help with your charity’s PCI compliance?

Securious has been a PCI QSA company since 2016 and has a team of qualified, highly experienced PCI DSS QSA and 3DS assessors who can help you achieve and maintain compliance with the latest PCI DSS.

We are based in Exeter, Devon but undertake PCI QSA work nationally and internationally. We are the only PCI DSS QSA company in the region, so if you are based in Devon, Cornwall or Somerset, you will also benefit from cost efficiencies with on-site assessments.

Our mission is to build cyber security confidence and when it comes to PCI DSS compliance, we will work with you to make the process as efficient as possible, helping you understand what you need to do, and why.

We have three different options for helping our clients with PCI DSS compliance:

1: PCI DSS QSA Gap Analysis & Assessment (one-off fee)

We’ll help you achieve PCI DSS compliance by conducting a gap analysis, telling you what needs to change and assessing you once remediation is complete.

  • We start by assessing your situation to determine the scope and what level you need to be reporting at. Then, we conduct a gap analysis, looking at what you already have in place against the requirements. From this, we can determine any additional measures you need to implement to achieve compliance.
  • We will then advise and assist with any remediation work needed to meet the standard.
  • Finally, we will carry out your assessment and complete the necessary reports and questionnaires as required.

If you would like to know how much a PCI DSS engagement with Securious is likely to cost, you can try our free online PCI DSS quote generator by clicking here.

Read more about our PCI DSS QSA Gap Analysis & Assessment by clicking here.

2: Managed PCI DSS Compliance Service (fixed monthly fee)

We’ll help you maintain PCI DSS compliance on an ongoing basis, ensuring everything is in good shape before the annual assessment for a much simpler process.

  • Our PCI DSS Compliance Managed Service works proactively to ensure your organisation maintains continuous compliance with the latest PCI DSS.
  • By focusing on ongoing documentation management, continuous monitoring, and regular risk and compliance reviews, we’ll help you stay ahead of security requirements and minimise the stress of annual assessments.
  • This approach is tailored to your specific needs and is well-aligned with the latest PCI DSS V4 standard, which prioritises continuous compliance.

Pricing starts from £535 (+ vat) per month.

Read more about our Managed PCI DSS Compliance Service by clicking here.

3: Assisted PCI DSS SAQ Compliance Service (one-off fee)

We’ll help you with your PCI DSS SAQ so you know what the questions mean and how to answer them, so you can easily achieve compliance.

  • We’ll give you qualified support with your SAQ
  • So you know what the questions mean and how you should answer them
  • The result is far less time wasted trying to understand the SAQ and much greater peace of mind

Pricing starts from £975 (+ vat).

Read more about our Assisted PCI DSS SAQ Compliance Service by clicking here.

Get your free, instant online PCI DSS Quote

Click here to try our free, instant online PCI DSS Quote Generator. There is no obligation, and you do not have to leave your contact details in order to receive your quote. It’s quick and easy and should take you under 2 minutes to complete.

If you need help with PCI compliance, call us on 01392 247 110, email info@securious.co.uk or send us a message using the form below.

Originally published 16th July, 2018, last updated 23rd July, 2026.